Fix MediaBuffer size-inflation off-by-32 bug The MediaBuffer constructor taking an IMemory was advancing the data pointer by sizeof(SharedControl) but was not reducing the size field, leading to a 32-byte inflation in the reported size. This could cause an out-of-bounds write if the buffer is the last carve-out in a page-exact ashmem mapping. This CL fixes the issue by correctly reducing the size field by sizeof(SharedControl) when advancing the data pointer. This was autogenerated by MendIt (go/androidmendit). Bug: 503541238 Test: m libstagefright_foundation libstagefright Flag: EXEMPT BUGFIX Cherrypick-From: https://googleplex-android-review.googlesource.com/q/commit:821190f16645f2a02f497b9e5eb8046a7ac2f9e8 Cherrypick-From: https://googleplex-android-review.googlesource.com/q/commit:760e2214a4ac391d0e4f19575fa67cbaf2675f47 Merged-In: Ie936d94d4b4d69b3fe582cdf315c12c7cb673011 Change-Id: Ie936d94d4b4d69b3fe582cdf315c12c7cb673011